HDPA (Greece) - 15/2026
Greece's DPA fines Ministry and Company €350K over data breach affecting 2.5M subjects.
Summary
Greece's Data Protection Authority (HDPA) has fined the Ministry of Social Cohesion and Family €200,000 and the Hellenic Local Development and Local Government Company €150,000 following a large-scale data breach. The breach, which affected approximately 2.5 million individuals, occurred due to outdated information systems and inadequate security measures at the processor's end. The DPA emphasized that public interest and lack of resources do not exempt organizations from their GDPR security obligations.
Full text
Help HDPA (Greece) - 15/2026: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 12:58, 3 September 2026 view source Sf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators46 edits Tag: Decisions [1.0]Newer edit → (No difference) Revision as of 12:58, 3 September 2026 HDPA - 15/2026 Authority: HDPA (Greece) Jurisdiction: Greece Relevant Law: Article 5(1)(f) GDPR Article 28(3) GDPR Article 32 GDPR Type: Other Outcome: n/a Started: Decided: 28.07.2026 Published: Fine: 200000.0 EUR Parties: Υπουργείο Κοινωνικής Συνοχής και Οικογένειας Ελληνική Εταιρεία Τοπικής Ανάπτυξης και Αυτοδιοίκησης National Case Number/Name: 15/2026 European Case Law Identifier: n/a Appeal: n/a Original Language(s): Greek Original Source: DPA.GR (in EL) Initial Contributor: sf The DPA fined the controller €200,000 and the processor €150,000, after a large-scale data breach affecting 2,500,700 data subjects occurred, due to outdated information systems, and inadequate security measures. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The Ministry of Social Cohesion and Family (the controller), and the Hellenic Local Development and Local Government Company (the processor) both notified the DPA after being subject to a data breach of the information systems operated by the processor. During the data breach, the databases supporting the implementation of two initiatives were encrypted and possibly downloaded/stolen. This included the data of staff, the legal representative of the organisation, the applicants, and the beneficiaries (which included children) affecting approximately 2,500,700 data subjects. The breach also allowed for unauthorised persons to gain access to the data held by the processor, and disruption of the systems. The controller claimed that it acted in compliance with the GDPR, notifying both the DPA and the processor immediately upon noticing the breach. The controller emphasised it took all necessary measures to address the incident, restore the availability of the systems, and minimise the impact on data subjects. The processor was made aware of the risks that its systems pose, and the need for their information system technologies to be improved and updated. Within which they claimed that they contacted the controller and other ministries to secure the necessary resources to allow the processor to address the vulnerabilities of its system. The processor emphasised it didn’t have the necessary financial resources to modernise the information systems, which was dependent entirely on state funding. Holding The DPA held in light of the incident being the result of a known, reasonably foreseeable, and exploitable technical vulnerability, the processor violated Article 5(1)(f) and Article 32 GDPR ensuring the security of its systems. The DPA emphasised that public interest and a lack of resources do not override the security obligation, and neither act as exemptions to this obligation. The DPA further contended that a violation of Article 32 GDPR by the processor does not exempt the controller from its obligations. The DPA therefore held, that the controller failed to ensure that the measures were adequate and to select a processor which provides adequate safeguards, correspondingly acting in violation of Article 5(1)(f) GDPR and Article 32 GDPR. Furthermore, in its investigation the DPA found that there was no active contract between the processor and the controller, covering the initiatives and thus the processing operations, the DPA found both the controller and processor in violation of Article 28(3) GDPR. As a result of the findings, the DPA imposed a fine of €200,000 on the data controller and 150,000 on the data processor, and ordered them to, effective immediately, enter into the contract required by Article 28(3) GDPR. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Greek original. Please refer to the Greek original for more details. Athens, July 28, 2026 Ref. No. 3163 DECISION 15/2026 The Data Protection Authority (hereinafter the “Authority”), met, upon invitation by the Acting Chair, Deputy , Georgios Batzalexis, for a meeting via teleconference on December 11, 2025, following a postponement from the meeting scheduled for December 2, 2025, in order to examine the case referred to in the background of this document. Present were the Deputy Chairman, Georgios Batzalexis, and the regular members Spyros Vlachopoulos, Konstantinos Lambrinoudakis, Charalambos Anthopoulos, Christos Kalloniatis, and Katerina Iliadou, as well as the alternate members Demosthenes Vougioukas, as rapporteur, and Maria Psalla, replacing regular member Grigoris Tsolias, who, although duly summoned in writing, did not was unable to attend due to a conflict of interest. Present, at the request of the Vice Chair, without the right to vote, were Georgia Panagopoulou and Ioannis Lykotrafitis, experts IT specialists, serving as assistant rapporteurs, and Irini Papageorgopoulou, an employee of the Authority’s Administrative Affairs Department, serving as secretary. The Authority took the following into consideration: The Ministry of Social Cohesion and Family (hereinafter “YKOISO”) submitted to the Authority, pursuant to Regulation (EU) 2016/679 (General Data Protection Regulation—hereinafter referred to as the GDPR), the notification with ref. no. Γ/ΕΙΣ/1943/07-03-2025 regarding a personal data breach. In this regard, the Hellenic Society for Local Development and Local Government S.A. (hereinafter EETAA) also submitted the ref. no. Γ/ΕΙΣ/1981/10-03-2025 regarding the same personal data breach incident. The notifications concerned data breaches information systems operated by EETA in its capacity as a processor acting on behalf of the controller, YKOISO. Subsequently, in response to an email (Ref. No. Ref. No. Γ/ΕΞΕ/846/10-03-2025) from the Authority to YKOISO, requesting clarifications regarding the type/categories of data affected by the incident, the type/categories and number of data subjects were affected, the roles of the involved entities with respect to the processing and the files that were affected; YKOISO submitted a document bearing ref. no. Γ/ΕΙΣ/2201/17- 03-2025, which states, among other things, the following: According to its report to the YKOISO dated March 6, 2025, the EEETAA suffered a series of cyberattacks, which were first detected on March 3, 2025, and continued to occur until March 5, 2025, at which time they were documented verified by the EETAA. These cyberattacks concerned personal data held by the EETAA for the purposes of implementing Action (a) “Promotion and support of children for their inclusion in preschool education, as well as for the access of school-age children, adolescents, and people with disabilities to creative activity services” (program “Daycare Centers”) for the periods 2014–2015 through 2024–2025 and the pilot App for Action (b) “Neighborhood Nannies.” It should be noted that, in accordance with the provisions of Joint Ministerial Decisions No. 99310 EX 2024 of July 10, 2024 (Government Gazette B 4056) and Joint Ministerial Decision No. 6457 of January 27, 2022 (Government Gazette B 205), respectively. Specifically, with regard to action (a) above, EETAA is the sole processor and is responsible for carrying out all processing operations related to the implementation, Surveillance, and management of the physical and financial scope of the action; in action (b) above, EETAA acts as a joint processor of data, together with the “National Network for Technology and Research Infrastructure S.A.” (EDYTE), although EDYTE’s role is limited primarily to processing related to the execution of payments and the management of the